ISC2 CGRC Practice Exam 125 Questions

Food & Hospitality

ISC2 CGRC PRACTICE EXAM 125 QUESTIONS Question 1: Which statement BEST distinguishes a policy from a procedure? Choices: 1) A policy is always technical; a procedure is always legal 2) A policy sta...

Study Guide Viewer

Loading secure 3-page preview…

Study Guide Preview

Extracted text from the free preview pages.

ISC2 CGRC PRACTICE

EXAM 125 QUESTIONS

Question 1: Which statement BEST distinguishes a policy from a procedure?

Choices:

1) A policy is always technical; a procedure is always legal 2) A policy states management intent and expectations; a procedure gives detailed steps for carrying them out 3) A procedure is approved only by external regulators 4) A policy is optional whenever a procedure exists Correct Answer: A policy states management intent and expectations; a procedure gives detailed steps for carrying them out Explanation: Policies communicate management direction and mandatory expectations.Procedures translate those expectations into repeatable operational steps.Page 1

Question 2: Which example is a technical control?

Choices:

1) Multi-factor authentication enforced by an identity platform 2) A security awareness policy 3) A governance committee charter 4) A background screening procedure

Correct Answer: Multi-factor authentication enforced by an identity platform

Explanation: Technical controls are implemented through hardware, software, or �rmware mechanisms. Multi-factor authentication enforced by a platform is a technical safeguard.Question 3: What is the MAIN di�erence between vulnerability scanning and penetration testing?

Choices:

1) Vulnerability scanning always proves business impact 2) Scanning identi�es potential weaknesses broadly; penetration testing actively attempts exploitation to demonstrate impact 3) Penetration testing never uses technical tools 4) They are identical methods with di�erent names Correct Answer: Scanning identi�es potential weaknesses broadly; penetration testing actively attempts exploitation to demonstrate impact Explanation: Vulnerability scanning is generally used to identify known weaknesses or miscon�gurations, while penetration testing goes further by attempting controlled exploitation to validate attack paths and impact.Page 2

Question 4: A control is partly implemented by a central identity service and partly by an application team. What type of control is this?

Choices:

1) System-speci�c control only 2) Common control only 3) Not applicable control 4) Hybrid control

Correct Answer: Hybrid control

Explanation: A hybrid control has both common and system-speci�c portions. Documentation must clearly allocate responsibility for each portion so gaps are not created.Question 5: A privacy review identi�es unresolved concerns about a new data use.What should occur before a �nal system compliance decision?

Choices:

1) Exclude privacy information because authorization is only technical 2) Assume consent resolves every privacy concern 3) Delete the privacy �nding 4) Include the privacy risk and required privacy documentation in the decision package and obtain appropriate review Correct Answer: Include the privacy risk and required privacy documentation in the decision package and obtain appropriate review Explanation: Current CGRC scope integrates security and privacy. Relevant privacy risks, assessments, and documentation should be part of the evidence presented to the appropriate decision-makers.Page 3

Get full access $39.00
Buy Now